Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Snowglobe

Also known as: Animal Farm, Snowglobe, ATK8

Description

**Toolset/Malware:** Babar, Bunny, Dino, Casper, Tafacalou, NBot, Chocopop **Notes:** Probably French origins

Goals & Targeting

Targeted Sectors

Government

AI Analysis

· 1 week ago

Executive Summary

Snowglobe is suspected to be a nation-state threat actor likely of French origin, primarily involved in espionage activities targeting government sectors. Known for using sophisticated malware such as Babar and Bunny, Snowglobe poses a significant threat to national security through persistent cyber operations.

Goals & Targeting

Snowglobe's primary motivation is espionage, targeting government sectors to collect intelligence. While their specific targeting by country isn't detailed, the toolset suggests they focus on high-value, sensitive sectors where information would be most beneficial to a nation-state's interests.

Enhanced Description

Snowglobe, also known as Animal Farm or ATK8, is a nation-state actor with suspected ties to France, focusing on espionage against government targets. The group's toolset includes malware like Babar, Bunny, Dino, Casper, Tafacalou, NBot, and Chocopop, indicating advanced capabilities in infiltrating and maintaining persistence within targeted networks. Their operations likely aim to gather sensitive information for strategic advantage, aligning with typical nation-state objectives.

Key Capabilities

  • Develops and deploys sophisticated malware
  • Engages in persistent cyber espionage
  • Targets government and possibly related sectors
  • Uses multiple tools/malware for varied attack vectors

MITRE ATT&CK Tactics

Reconnaissance
Exfiltration

ATT&CK Techniques

T1059
T1059.003
T1566
T1566.004

Software / Tooling

Babar
Bunny
Dino
Casper
Tafacalou
NBot
Chocopop

Campaigns & Victims

Snowglobe's campaigns likely involve targeted attacks using their malware toolset, focusing on long-term persistence to exfiltrate sensitive data. While specific campaign details are scarce, the group’s activity suggests a focus on governmental targets, possibly linked to French strategic interests.

IOC Patterns

  • Use of custom malware for initial access
  • Spear-phishing emails with malicious attachments
  • Lateral movement within networks post-initial breach

Recommended Actions

  • Implement advanced email filtering to detect spear-phishing attempts
  • Monitor for unusual network activity indicative of C2 communication
  • Deploy endpoint detection and response (EDR) solutions to identify malicious processes
  • Conduct regular audits of software supply chains for potential compromises

Suggested Tags

APT
espionage
government-targeted

Confidence Assessment

Confidence in Snowglobe's nation-state origin is medium, with much inferred rather than directly confirmed. Gaps exist regarding exact origin and specific campaigns linked to the group.

ATT&CK Techniques

No techniques linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

7

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
espionage
government-targeted

Details

Type
Nation-State
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
F
Confidence
70%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.